GitHub confirms breach of 3800 repos via malicious VSCode extension
Sergiu Gatlan reports GitHub has confirmed that roughly 3800 internal repositories were breached after one of its employees installed a malicious VS Code extension The company has since removed the unnamed trojanized extension from the VS Code marketplace and has secured the compromised device Yesterday we detected and contained a compromise of an employee device Source